{"id":"CVE-2026-89736","title":"kernel: usb: gadget: u_audio: Fix use-after-free on sound card disconnect (CVE-2026-89736)","summary":"A flaw was found in the Linux kernel's USB audio gadget driver (u_audio). This vulnerability occurs during sound card disconnection when Asynchronous Linux Sound Architecture (ALSA) control elements (kctls) remain open in userspace. A loca…","severity":"medium","cvss":5.5,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","cvssSource":"vendor","cwe":"CWE-825","vendor":"Red Hat","product":"Linux","affected":["Linux >= 33f341c1fc60e172a3515c51bdabee11e83d1ee9 < a7ecd1a04f4f485d7be6443d0f0b2c61a800cb82","Linux >= b131989797f7287d7fdadb2bababc05a15d44750 < f983793f03148b097977f200298db215cd2d4438","Linux >= 3bc7324e4911351e39c54a62e6ca46321cb10faf < 6f46762196f04464e1050a9ee94e72b917db9010","Linux >= 6c67ed9ad9b83e453e808f9b31a931a20a25629b < 891a8d11f4d5eb50b2ce7570f4f98204a7a57493","Linux >= 6c67ed9ad9b83e453e808f9b31a931a20a25629b < c74ff0b1a0fca53d3ac185873c87d6a719b30a47","Linux >= 6c67ed9ad9b83e453e808f9b31a931a20a25629b < 4e747c864a88537e18b1ffc19a1954c9686bb8e1","Linux >= 6c67ed9ad9b83e453e808f9b31a931a20a25629b < 79a92896e2bb9471550c56fc23d8d93592f04c27","Linux >= 6c67ed9ad9b83e453e808f9b31a931a20a25629b < 858965947081d10d41d9a1010a540d3d5eea958b","Linux 3e016ef2e72da93a2ea7afbb45de1b481b44d761","Linux 3256e152b645fc1e788ba44c2d8ced690113e3e6","Linux 0eda2004f38d95ef5715d62be884cd344260535b","Linux 43ca70753dfffd517d2af126da28690f8f615605","Linux >= 5.10.177 < 5.10.270","Linux >= 5.15.105 < 5.15.221","Linux >= 6.1.22 < 6.1.188","Linux >= 4.14.312 < 4.15","Linux >= 4.19.280 < 4.20","Linux >= 5.4.240 < 5.5","Linux >= 6.2.9 < 6.3","Linux 6.3"],"published":"2026-09-11","updated":"2026-09-21","sourceUpdated":"2026-09-21T17:28:09+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89736.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89736.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-89736"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2532311"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-89736"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-89736"},{"url":"https://git.kernel.org/pub/scm/linux/security/vulns.git/plain/cve/published/2026/CVE-2026-89736.mbox"},{"url":"https://git.kernel.org/stable/c/a7ecd1a04f4f485d7be6443d0f0b2c61a800cb82"},{"url":"https://git.kernel.org/stable/c/f983793f03148b097977f200298db215cd2d4438"},{"url":"https://git.kernel.org/stable/c/6f46762196f04464e1050a9ee94e72b917db9010"},{"url":"https://git.kernel.org/stable/c/891a8d11f4d5eb50b2ce7570f4f98204a7a57493"},{"url":"https://git.kernel.org/stable/c/c74ff0b1a0fca53d3ac185873c87d6a719b30a47"},{"url":"https://git.kernel.org/stable/c/4e747c864a88537e18b1ffc19a1954c9686bb8e1"},{"url":"https://git.kernel.org/stable/c/79a92896e2bb9471550c56fc23d8d93592f04c27"},{"url":"https://git.kernel.org/stable/c/858965947081d10d41d9a1010a540d3d5eea958b"}],"tags":["csaf","vex","red-hat","cve.org","score-dispute"],"epss":0.00126,"epssPercentile":0.02627,"scores":{"vendor":5.5,"cna":7.8},"ingestedAt":"2026-09-14T15:23:07.449Z","slug":"CVE-2026-89736","body":"## Overview\n\nA flaw was found in the Linux kernel's USB audio gadget driver (u_audio). This vulnerability occurs during sound card disconnection when Asynchronous Linux Sound Architecture (ALSA) control elements (kctls) remain open in userspace. A local attacker can exploit this timing issue by interacting with these kctls, leading to a use-after-free memory corruption. This could potentially result in arbitrary code execution or a denial of service.\n\n## Vendor advisories\n\n- **Red Hat VEX** · Moderate · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89736.json)\n\n**kernel: usb: gadget: u_audio: Fix use-after-free on sound card disconnect** — rated Moderate by Red Hat. Released 2026-09-11, updated 2026-09-21.\n\nNot affected:\n\n- Red Hat Enterprise Linux 10\n- Red Hat Enterprise Linux 6\n- Red Hat Enterprise Linux 7\n- Red Hat Enterprise Linux 8\n- Red Hat Enterprise Linux 9\n- Red Hat OpenShift Container Platform 4\n\n## Remediation\n\nRefer to the advisory for fix availability.","depth":"sunlit","depthScore":30,"depthScoreParts":{"impact":30.3,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[{"seq":208956,"id":"CVE-2026-89736","ts":1790062299134,"field":"cvss","old":"7.8","new":"5.5"},{"seq":208955,"id":"CVE-2026-89736","ts":1790062299134,"field":"severity","old":"high","new":"medium"},{"seq":197687,"id":"CVE-2026-89736","ts":1789384318410,"field":"cvss","old":"7","new":"7.8"},{"seq":183850,"id":"CVE-2026-89736","ts":1789356677670,"field":"cvss","old":"7.8","new":"7"},{"seq":153620,"id":"CVE-2026-89736","ts":1789285351534,"field":"cvss","old":null,"new":"7.8"},{"seq":153619,"id":"CVE-2026-89736","ts":1789285351534,"field":"severity","old":"none","new":"high"},{"seq":147383,"id":"CVE-2026-89736","ts":1789270210688,"field":"cvss","old":null,"new":"7"},{"seq":147382,"id":"CVE-2026-89736","ts":1789270210688,"field":"severity","old":"none","new":"high"},{"seq":109137,"id":"CVE-2026-89736","ts":1789183730454,"field":"cvss","old":null,"new":"7"},{"seq":109136,"id":"CVE-2026-89736","ts":1789183730454,"field":"severity","old":"none","new":"high"}]}